6 days ago

US Disrupts Chinese QTFY Botnet Targeting Critical Infrastructure

US Disrupts Chinese QTFY Botnet Targeting Critical Infrastructure
US disrupts Chinese botnet network QTFY: China waging shadow war against rivals · opindia.com

US officials say they stopped a Chinese-linked hacking network called QTFY.

The network used two tools, QScan and QTRouter.

QScan searched for internet-connected devices such as routers and cameras and infected some of them.

QTRouter then used those devices to make attacks look as if they came from somewhere other than China.

Officials said the network targeted important US organizations and other sensitive networks.

They seized internet domains that the tools needed to communicate and work.

This made the two platforms unusable, according to the Justice Department.

China denies wrongdoing, while US officials describe the operation as part of a wider cyber-espionage threat.

Key facts

Disruption method
Court-authorized seizures of domains used by QScan and QTRouter.
Attributed group
QTFY, described by US authorities as a Chinese state-sponsored cyber-espionage group.
Associated company
Nanjing Xinjiuwei Network Technology Company, based in China.
QScan function
Scanning and automatically infecting internet-connected devices globally.
QTRouter function
Using compromised IoT devices, commercial proxy-service devices, and leased virtual private servers to obscure attack origins.
Reported activity period
The network was active from at least 2018 through 2026, according to the article.
Reported targets
NASA, the Federal Reserve, the Department of Energy, the Department of Justice, health agencies, the Senate, hospitals, telecommunications providers, power companies, financial institutions, and defense contractors.

Quotes

US Justice Department and FBI

US law-enforcement agencies announcing the court-authorized disruption of QTFY’s hacking platforms

“The Justice Department and FBI announced court-authorised domain seizures today to deny malicious cyber actors access to two complementary hacking platforms known as “QScan” and “QTRouter,” used to target U.S. critical infrastructure and other sensitive networks.”
opindia.com

Sources

Related news